URL: https://github.com/SSSD/sssd/pull/837 Title: #837: p11_child: make OCSP digest configurable
simo5 commented: """ @alexey-tikhonov if there is a compatibility issue, I would certainly allow SHA-1 to be used, but perhaps with an easier way to flip it off in future. Alsthough it is true @dpward that SHA-1 is allowed, you need to read the fine print as well "for applications that do not require collision resistance". Basically this exclude unique identifier if those are used in any "security" sense, while you still can use SHA-1 in applications where a collision is handled appropriately (for example hash-maps). So it really depend more and more on the kinds of usage, which is why it is preferable, where possible, to simply move off of SHA-1. """ See the full comment at https://github.com/SSSD/sssd/pull/837#issuecomment-674968818
_______________________________________________ sssd-devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
